
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69199 is a denial-of-service vulnerability in Pterodactyl Wings, the server control plane for the open-source game server management panel. The flaw stems from the absence of rate limiting and throttling on WebSocket connections, allowing low-privileged users to exhaust host network, CPU, and memory resources. All Wings versions prior to 1.12.0 are affected. The advisory was published on January 19, 2026, with a CVSS v3.1 score of 6.5 (Medium) and a CVSS v4.0 score of 8.3 (High) (GitHub Advisory, Pterodactyl Advisory).
The root cause is classified under CWE-400 (Uncontrolled Resource Consumption) and CWE-770 (Allocation of Resources Without Limits or Throttling). Wings' WebSocket endpoints impose no restrictions on the number of concurrent connections a user may open, nor on the total size of messages sent or received over those connections. An attacker with low-level panel access can open thousands of simultaneous WebSocket connections and flood them with large payloads, triggering resource exhaustion on the host. No complex preconditions are required beyond possessing a valid (potentially free-tier) account on the Pterodactyl panel (GitHub Advisory, Pterodactyl Advisory).
Successful exploitation results in a denial-of-service condition affecting the availability of the Wings daemon and the underlying host system. An attacker can saturate host network bandwidth, exhaust available memory, and spike CPU utilization to the point where the Wings service becomes unresponsive, disrupting all game servers managed by the affected node. There is no confidentiality or integrity impact; the attack is purely an availability concern, but it can affect all tenants sharing the same Wings host (GitHub Advisory).
No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation at this time (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.081% (24th percentile), indicating a low near-term exploitation probability. The attack requires only low privileges (a valid panel account) and no user interaction, making it straightforward to execute if an attacker has panel access (GitHub Advisory).
websockets or wscat) to open thousands of simultaneous WebSocket connections to the Wings daemon using the authenticated session token.wings binary); rapid growth in Wings process memory consumption; system OOM (out-of-memory) killer events in /var/log/syslog or dmesg referencing the Wings process.The primary remediation is to upgrade Wings to version 1.12.0, which introduces proper rate limiting and throttling on WebSocket connections (GitHub Advisory, Pterodactyl Advisory). For operators unable to upgrade immediately, the following network-level mitigations are recommended:
The vulnerability was reported by security researcher KianBrose and published by the Pterodactyl maintainer anthonyphysgun on January 19, 2026 (Pterodactyl Advisory). A brief technical write-up was published by Infinit Security shortly after disclosure (Infinit Security). No significant broader media coverage or notable social media discussion has been observed beyond standard vulnerability aggregator postings.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."